Executive brief
In Apache HTTP Server versions 2.4.17 to 2.4.38, a local privilege escalation vulnerability exists when using MPM event, worker, or prefork. A less-privileged child process or thread can execute arbitrary code with the privileges of the parent process (typically root) by manipulating the scoreboard. This issue affects Unix-based systems only.
Affected products
- Apache HTTP Server 2.4.17 to 2.4.38
Timeline
- 2019-04-02: disclosed: Initial public disclosure via oss-security mailing list.
- 2021-11-03: advisory: NVD publication date.